Data Processing Agreement
Version 1.0 · Effective date: July 15, 2026 · Last updated: August 18, 2026
This Data Processing Agreement ("DPA") supplements the Terms of Service between you ("Customer", acting as controller, or as processor on behalf of your own customers) and Fitable SL ("Fitable", "we", "us", acting as processor) whenever Fitable processes personal data on your behalf through fitable.es and the Fitable services (the "Services"). It implements Article 28 of the EU General Data Protection Regulation ("GDPR").
Where anything in this DPA conflicts with the Terms of Service on data-processing matters, this DPA prevails. Terms not defined here have the meaning given in the Privacy Policy or the Terms of Service.
In short:
- Fitable processes personal data only on your documented instructions — set through your use of the Services and this DPA — and never for its own purposes.
- Fitable applies the security measures described in the Privacy Policy §16 and binds every sub-processor to the same obligations under its own Article 28 agreement.
- The authorized sub-processor list is the one published in the Privacy Policy §9, kept current there so this DPA never drifts out of sync with who actually processes your data.
- You can request assistance, audit information and deletion/return of data as described below, free of charge for reasonable requests.
1. Roles of the parties
- Customer is the controller of the personal data it submits to the Services (or a processor acting on behalf of its own controller, in which case Customer warrants it has the authority to enter into this DPA on that controller's behalf).
- Fitable is the processor, processing personal data solely to provide the Services as instructed by Customer.
2. Subject matter, duration, nature and purpose
- Subject matter — personal data contained in Customer Content (product photography, brand assets, storefront and social data) that Customer submits to the Services, and any personal data of end users incidentally included in imagery Fitable generates or analyzes at Customer's request.
- Duration — for as long as Fitable provides the Services to Customer under the Terms of Service, plus the retention periods described in the Privacy Policy §11.
- Nature of processing — collection, storage, AI-based generation and analysis, hosting, and deletion of Customer Content, as described in the Privacy Policy §§3, 4 and 6.
- Purpose — to provide, secure and support the Services Customer has purchased, and no other purpose.
3. Categories of data subjects and personal data
- Data subjects — Customer's authorized users; individuals who may appear in Customer's uploaded content (e.g. models, staff, customers depicted in user-generated content); and individuals who may appear in publicly available content Customer directs Fitable to analyze (e.g. a connected storefront or public social feed).
- Categories of personal data — account identifiers (name, email); images of people contained in uploaded or analyzed content; names or handles visible in public content; and usage/log data generated while Customer's authorized users operate the Services. Fitable does not intentionally process special categories of data (Article 9 GDPR) and Customer warrants it will not submit such data through the Services without Fitable's prior written agreement on additional safeguards.
4. Fitable's obligations as processor
Fitable shall:
- Process only on documented instructions from Customer, including regarding international transfers, unless required to do otherwise by EU or Member State law — in which case Fitable will inform Customer of that legal requirement before processing, unless the law prohibits this on important grounds of public interest. Customer's instructions are given by configuring and using the Services and by this DPA; the Terms of Service and Privacy Policy describe how that data is used, which constitutes Customer's documented instruction for that processing.
- Confidentiality — ensure that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Security — implement the technical and organisational measures described in the Privacy Policy §16, appropriate to the risk, per Article 32 GDPR.
- Sub-processor authorization — engage sub-processors only as permitted under section 5 below.
- Assistance — taking into account the nature of the processing, assist Customer by appropriate technical and organisational measures, insofar as reasonably possible, for the fulfilment of Customer's obligation to respond to requests for exercising data subjects' GDPR rights.
- Breach notification — notify Customer without undue delay after becoming aware of a personal data breach affecting Customer's data, providing the information reasonably available to enable Customer to meet its own Article 33/34 obligations. This supplements, and does not replace, Fitable's own regulator-notification duty described in the Privacy Policy §16.
- DPIA and prior consultation assistance — assist Customer, taking into account the nature of processing and the information available to Fitable, with data protection impact assessments and prior consultations with supervisory authorities where required by Articles 35-36 GDPR.
- Deletion or return — at Customer's choice, delete or return all personal data to Customer after the end of the provision of the Services, and delete existing copies, per the retention schedule in the Privacy Policy §11 — unless EU or Member State law requires storage of the personal data.
- Audit information — make available to Customer all information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, subject to section 7 below.
5. Sub-processors
Customer authorizes Fitable to engage the sub-processors listed in the Privacy Policy §9, as that list is updated from time to time. Fitable:
- Imposes on every sub-processor, by contract, data-protection obligations equivalent to those set out in this DPA, in particular the security measures required by Article 32 GDPR.
- Remains fully liable to Customer for a sub-processor's failure to fulfil its data-protection obligations.
- Will give Customer notice of any change in the Privacy Policy §9 sub-processor list by publishing the updated policy — the same 30-day material-change notice period described in the Privacy Policy §17 applies. Customer may object to a new sub-processor on reasonable data-protection grounds within that window by emailing fitable.ai@gmail.com; if the parties cannot resolve the objection, Customer's remedy is to terminate the affected Services per the Terms of Service.
6. International transfers
Where personal data is transferred outside the EU/EEA — to the sub-processors listed in the Privacy Policy §9 — Fitable relies on the safeguards described in the Privacy Policy §10 (the EU-US Data Privacy Framework where the recipient is certified, and the European Commission's Standard Contractual Clauses as the fallback mechanism). Those safeguards are incorporated into this DPA by reference and apply to every transfer made in connection with the Services.
7. Audits
Fitable makes the compliance information described in section 4 available on request. Where that information does not resolve Customer's audit request, Customer may conduct an on-site or remote audit of Fitable's processing activities directly relevant to Customer's data, no more than once per 12-month period absent a specific indication of non-compliance, on at least 30 days' written notice, during business hours, in a manner that does not unreasonably interfere with Fitable's operations or expose other customers' data, and subject to a mutually agreed confidentiality undertaking. Customer bears its own costs of an audit; Fitable may charge for time reasonably spent supporting an audit beyond the information already made available under section 4.
8. Liability
Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
9. Governing law
This DPA is governed by Spanish and EU law, consistent with the Imprint and the Terms of Service, without prejudice to any data-protection rights a data subject holds under mandatory law regardless of choice of law.
10. Term and termination
This DPA takes effect on the date Customer first submits personal data to the Services and remains in effect for as long as Fitable processes personal data on Customer's behalf under the Terms of Service. Either party may terminate this DPA by terminating the underlying Services in accordance with the Terms of Service; termination does not affect processing that has already occurred.
11. Changes to this DPA
- Material changes take effect no earlier than 30 days after we notify you by email or in-app notice, consistent with the Terms of Service.
- Non-material changes (clarifications, typos, contact updates) take effect on posting.
- Prior versions are available on request at fitable.ai@gmail.com.
This DPA is published in English, Spanish and Catalan; in case of discrepancy the English version prevails, except where mandatory law grants a consumer the version in the language in which the Services were marketed to them.
12. Contact
- Data-processing questions: fitable.ai@gmail.com
- Legal notices: fitable.ai@gmail.com
See also the Terms of Service and the Privacy Policy.
